F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP Access Policy Manager (APM) has been exploited in remote code execution attacks. The flaw affects BIG-IP APM instances configured as an OAuth Authorization Server with an access policy and OAuth profile on a virtual server. Deployments using APM only as an OAuth Client or Resource Server without authorization server profiles are not affected. F5 has released security updates to address this issue and provided an iRule mitigation for those unable to patch immediately. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities Catalog and mandated remediation by U.S. federal agencies. The vulnerability has been actively exploited, and F5 advises monitoring for indicators such as multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT.
AI Analysis
Technical Summary
CVE-2026-94127 is a critical zero-day vulnerability in F5 BIG-IP APM affecting instances configured as OAuth Authorization Servers with specific access policies and OAuth profiles on virtual servers. The flaw enables remote code execution and has been actively exploited in the wild. F5 has released security updates to fix the vulnerability and provided an iRule mitigation for immediate protection. The vulnerability is tracked by CISA, which has mandated U.S. federal agencies to patch promptly. Deployments using APM solely as OAuth Clients or Resource Servers without authorization server profiles are not vulnerable. Indicators of compromise include multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT events. Shadowserver tracks over 14,700 IPs with BIG-IP APM fingerprints, though the patch status of these is unknown.
Potential Impact
The vulnerability allows remote code execution on affected BIG-IP APM systems configured as OAuth Authorization Servers, potentially enabling attackers to execute arbitrary commands. This poses significant risks to organizations relying on BIG-IP APM for centralized access management, including unauthorized access, network compromise, and data breaches. The flaw has been actively exploited, prompting urgent remediation directives from CISA for U.S. federal agencies. Deployments not configured as OAuth Authorization Servers are not impacted.
Mitigation Recommendations
F5 has released official security updates that fix this vulnerability and should be applied immediately. For environments unable to patch promptly, F5 provides an iRule mitigation available from F5 Support to apply to the affected BIG-IP APM virtual servers. Customers are advised to monitor for indicators of compromise such as multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT events. Follow F5's official advisory for detailed remediation steps and apply patches as soon as possible.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
Description
A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP Access Policy Manager (APM) has been exploited in remote code execution attacks. The flaw affects BIG-IP APM instances configured as an OAuth Authorization Server with an access policy and OAuth profile on a virtual server. Deployments using APM only as an OAuth Client or Resource Server without authorization server profiles are not affected. F5 has released security updates to address this issue and provided an iRule mitigation for those unable to patch immediately. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities Catalog and mandated remediation by U.S. federal agencies. The vulnerability has been actively exploited, and F5 advises monitoring for indicators such as multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94127 is a critical zero-day vulnerability in F5 BIG-IP APM affecting instances configured as OAuth Authorization Servers with specific access policies and OAuth profiles on virtual servers. The flaw enables remote code execution and has been actively exploited in the wild. F5 has released security updates to fix the vulnerability and provided an iRule mitigation for immediate protection. The vulnerability is tracked by CISA, which has mandated U.S. federal agencies to patch promptly. Deployments using APM solely as OAuth Clients or Resource Servers without authorization server profiles are not vulnerable. Indicators of compromise include multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT events. Shadowserver tracks over 14,700 IPs with BIG-IP APM fingerprints, though the patch status of these is unknown.
Potential Impact
The vulnerability allows remote code execution on affected BIG-IP APM systems configured as OAuth Authorization Servers, potentially enabling attackers to execute arbitrary commands. This poses significant risks to organizations relying on BIG-IP APM for centralized access management, including unauthorized access, network compromise, and data breaches. The flaw has been actively exploited, prompting urgent remediation directives from CISA for U.S. federal agencies. Deployments not configured as OAuth Authorization Servers are not impacted.
Mitigation Recommendations
F5 has released official security updates that fix this vulnerability and should be applied immediately. For environments unable to patch promptly, F5 provides an iRule mitigation available from F5 Support to apply to the affected BIG-IP APM virtual servers. Customers are advised to monitor for indicators of compromise such as multiple OAuth authentication failures and suspicious commands followed by TMM SIGABRT events. Follow F5's official advisory for detailed remediation steps and apply patches as soon as possible.
Technical Details
- Classification
- {"confidence":0.94,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/","fetched":true,"fetchedAt":"2026-09-23T07:17:59.843Z","wordCount":718}
Threat ID: 6ab37d27f7a7c541066f29c3
Added to database: 09/23/2026, 07:17:59 UTC
Last enriched: 09/23/2026, 07:18:08 UTC
Last updated: 09/23/2026, 08:01:37 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.